Vulnerability Bulletins

CVE-2026-43170

   
Affected software LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: gadget: Move vbus draw to workqueue context

Currently dwc3_gadget_vbus_draw() can be called from atomic
context, which in turn invokes power-supply-core APIs. And
some these PMIC APIs have operations that may sleep, leading
to kernel panic.

Fix this by moving the vbus_draw into a workqueue context.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-43170